Sign inSign up

vulners/opencti-connector

By vulners

•Updated 4 months ago

Enrich OpenCTI CVEs with exploits, EPSS, CISA KEV, and affected software from Vulners 200+ sources.

Image
Security
0

945

vulners/opencti-connector repository overview

⁠Vulners OpenCTI Connector

On-demand vulnerability enrichment for OpenCTI⁠. When a CVE appears in your instance, Vulners adds the context NVD doesn't provide — exploits, affected software, vendor advisories, EPSS, CISA KEV, and complete CVSS vectors.

Type: Internal Enrichment · Scope: Vulnerability


⁠What It Does

The connector triggers when a Vulnerability entity is created or manually enriched in OpenCTI. It calls the Vulners API and writes structured STIX 2.1 objects back into your instance.

One connector replaces three. Vulners enrichment includes EPSS scoring, CISA KEV status, and full CVSS vectors — no need for separate connectors for each signal.

⁠Enrichment at a glance

CVE enriched by Vulners — data coverage overview showing affected software, exploits, and reports

SignalNVD Import Only+ Vulners (Free)+ Vulners (Paid)
CVSS v3 vectorPartialFull (all fields)Full
EPSS score & percentile—YesYes
CISA KEV status—Yes + first-seen dateYes
Semantic labels—Auto-generatedAuto-generated
Data coverage overview—Counts (e.g. 72 products, 3 exploits, 10 reports)Counts
Affected software—Summary count + stub entityNamed products with CPE & versions
Exploits & tools—Summary count + stub entityNamed exploits with details
Reports & analysis—Summary count + stub entityFull report content & titles
Cross-CVE software linking——Pivot from product → all its CVEs
Vulners AI Score——Proprietary risk score
CWE classification——Yes
⁠Free tier — genuinely useful

Available to all users with a free Vulners API key. No CVE limits, no quotas.

Free enrichment answers the critical prioritization questions: Does an exploit exist? How many products are affected? Is this in CISA KEV? What's the EPSS percentile? The data coverage overview table — showing counts like "72 affected products, 3 exploits, 10 reports" — appears directly in the CVE description.

Stub entities for software, tools, and reports are clean single records reused across all enriched CVEs. No database bloat, no orphaned objects. Each stub carries an upgrade path to full intelligence.

Stub entity with upgrade path

⁠Paid tier — operational detail

Paid enrichment adds the "which" and "what": named product versions with CPE strings, exploit PoC names, full threat intel reports with titles and dates. Software observables with CPE strings link across CVEs sharing the same affected configuration — pivot from any product to every CVE that hits it.


⁠Why On-Demand, Not Bulk

Bulk import connectors pull every CVE, every exploit, every advisory on a 24-hour cycle. That means 200k+ CVEs loaded whether your team tracks them or not — and their own docs warn this requires clustered OpenCTI infrastructure.

Vulners takes the opposite approach. As an internal enrichment connector, it fires only when a CVE actually appears in your instance. You get deep context on the vulnerabilities that matter to your organization, with a single lightweight container. No cluster required.

Bulk ImportVulners Enrichment
ArchitectureExternal Import (scheduled)Internal Enrichment (on-demand)
TriggersEvery 24h, pulls everythingWhen a CVE appears in YOUR data
Data volumeAll CVEs regardless of relevanceOnly what matters to your org
InfrastructureMay need clustered deploymentSingle container

⁠Quick Start

⁠docker-compose.yml
services:
  vulners-enrichment:
    image: vulners/opencti-connector:latest
    environment:
      - OPENCTI_URL=http://opencti:8080
      - OPENCTI_TOKEN=${OPENCTI_ADMIN_TOKEN}
      - CONNECTOR_ID=${VULNERS_CONNECTOR_ID}  # Generate with: uuidgen
      - CONNECTOR_NAME=Vulners Enrichment
      - CONNECTOR_TYPE=INTERNAL_ENRICHMENT
      - CONNECTOR_SCOPE=Vulnerability
      - CONNECTOR_AUTO=true
      - CONNECTOR_LOG_LEVEL=info
      - VULNERS_API_KEY=${VULNERS_API_KEY}
    restart: always

Set CONNECTOR_AUTO=true to enrich every new Vulnerability automatically. Set to false for manual enrichment only.

⁠Get Your API Key
  1. Sign up at vulners.com⁠ (free)
  2. Go to Profile → API Keys
  3. Generate a key and set it as VULNERS_API_KEY

⁠Environment Variables

VariableRequiredDefaultDescription
OPENCTI_URLYes—OpenCTI platform URL
OPENCTI_TOKENYes—OpenCTI API token
CONNECTOR_IDYes—Unique connector UUID (uuidgen)
CONNECTOR_NAMENoVulners EnrichmentDisplay name in OpenCTI
CONNECTOR_TYPENoINTERNAL_ENRICHMENTConnector type
CONNECTOR_SCOPENoVulnerabilityEntity types to enrich
CONNECTOR_AUTONofalseAuto-enrich new entities
CONNECTOR_LOG_LEVELNoinfoLogging level
VULNERS_API_KEYYes—Your Vulners API key
VULNERS_API_URLNohttps://vulners.comVulners API endpoint
VULNERS_MAX_TLPNoTLP:AMBERMaximum TLP marking level

⁠STIX Objects Created

The connector creates and links these STIX 2.1 objects:

  • Vulnerability — enriched with EPSS, KEV, CVSS, labels, description with data coverage overview
  • Software (Observable) — affected products with CPE strings (paid) or summary stub (free)
  • Tool — exploit PoCs and tools (paid: named, free: summary stub)
  • Report — vendor advisories and threat intel articles (paid: full content, free: summary stub)
  • Relationships — HAS (vulnerability → software), TARGETS (vulnerability → tool)


Built by Vulners⁠ — vulnerability intelligence from 218+ sources, 235k+ CVEs, 256k+ exploits.

Tag summary

Content type

Image

Digest

sha256:ac33ea4aa…

Size

168.1 MB

Last updated

4 months ago

docker pull vulners/opencti-connector